Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 627

Количество 390 627

nvd логотип

CVE-2026-56413

3 месяца назад

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-56412

3 месяца назад

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-56411

3 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56410

3 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-5640

5 месяцев назад

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-56409

3 месяца назад

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56408

3 месяца назад

libexpat before 2.8.2 has an integer overflow in copyString.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56407

3 месяца назад

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56406

3 месяца назад

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56405

3 месяца назад

libexpat before 2.8.2 has an integer overflow in getAttributeId.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56404

3 месяца назад

libexpat before 2.8.2 has an integer overflow in addBinding.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56403

3 месяца назад

libexpat before 2.8.2 has an integer overflow in storeAtts.

CVSS3: 6.9
EPSS: Низкий
nvd логотип

CVE-2026-56402

3 месяца назад

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-56401

2 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
nvd логотип

CVE-2026-56400

2 месяца назад

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-5639

5 месяцев назад

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-56399

3 месяца назад

Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-56398

2 месяца назад

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-56397

3 месяца назад

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2026-56396

3 месяца назад

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.

CVSS3: 10
4%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56412

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.

CVSS3: 4.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56411

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56410

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5640

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56409

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56408

libexpat before 2.8.2 has an integer overflow in copyString.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56407

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56406

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56405

libexpat before 2.8.2 has an integer overflow in getAttributeId.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56404

libexpat before 2.8.2 has an integer overflow in addBinding.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56403

libexpat before 2.8.2 has an integer overflow in storeAtts.

CVSS3: 6.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56402

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56401

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

2 месяца назад
nvd логотип
CVE-2026-56400

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

CVSS3: 8.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5639

A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-56399

Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.

CVSS3: 5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56398

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

CVSS3: 7.3
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-56397

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

CVSS3: 9.6
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.

CVSS3: 8.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу